1 finding · 4 warnings · 4 checks passed
Vendors
p9A1NLsdHX01adTVGrfNvaScjwhGGM_cfsa.B8kAAWX.87G-C98FX2HV16G-CD0K5K18SGGTM-TM3S526Violations
GCM_002Do not write analytics or advertising cookies until the visitor has made a consent choice. Load GTM/GA4 tags behind a denied consent default and let the CMP's update unblock them.
GCM_010Affected: Criteo, Seznam Sklik
After a rejection the affected vendors must stop setting identifiers and sending measurement, or run only in a verified cookie-less mode.
GCM_003Make both the accept and the reject button update the consent state through the GTM Consent API or gtag('consent', 'update').
GCM_008Affected: lazy_no_update
Call gtag('consent', 'update') immediately after the visitor's choice, with the correct values for both accept and reject. Do not rely on a page reload: it creates duplicate pageviews and breaks session attribution.
GCM_009Affected: Criteo, Seznam Sklik
The affected vendors set an identifier or sent measurement that is not verifiably cookie-less before the visitor chose. Load them only after consent, or configure a documented cookie-less mode that sends no identifiers.
GCM_012Affected: Gemius, Google Analytics 4
No identifier was observed, but the visitor's IP address and page context still reached a third party before consent. To be compliant under this check, load the vendor only after consent.